CVE-2026-73581
📛 CVE Title
Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
Description
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- apache
- CVSS severity
- —
- CVSS score
- —
- CVSS vector
- —
- Effective score
- 6.5 / 10 MEDIUM source: NVD
- CWE(s)
-
CWE-299 - Reserved
- 2026-08-13
- Published
- 2026-09-23 11:08 UTC
- Last updated
- 2026-09-23 18:10 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/73xxx/CVE-2026-73581.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-23 12:17:06 UTC
- NVD last modified
- 2026-09-23 19:19:13 UTC
- NVD CVSS v3.1
- 6.5 / 10 MEDIUM source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 2.5 / 10
NVD / KEV / EPSS data refreshed 2026-09-24 04:36 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85222 - Assigner
- apache
- Published
- Sep 23, 2026, 11:08:53 AM
- Updated
- Sep 23, 2026, 6:10:39 PM
- EUVD base score (CVSS 3.1)
-
6.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EUVD-reported EPSS
- 0.0000
- Vendors
- Apache Software Foundation
- Products
-
Apache Tomcat (10.1.0-M1 ≤10.1.59)Apache Tomcat (11.0.0-M1 ≤11.0.25)Apache Tomcat (9.0.0.M1 ≤9.0.121)Apache Tomcat (8.5.0 ≤8.50.100)
- Aliases
-
GHSA-cf68-55f3-8gfw
ENISA description: Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat |
11.0.0-M1 (affected),
10.1.0-M1 (affected),
9.0.0.M1 (affected),
8.5.0 (affected),
0 (unaffected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do vendor-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://www.openwall.com/lists/oss-security/2026/09/23/19 af854a3a-2127-422b-91ae-364da2661108
- https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do security@apache.org
Remediations (10)
-
web:anonhaven.com
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE …
2026-09-24 11:51 UTC -
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the vendor‑published update to the Apache Tomcat installation, updating to version 11.0.26, 10.1.59, or 9.0.122, which includes the CRL‑checking fix .
2026-09-24 11:51 UTC -
web:cvetodo.com
CVE-2026-73581 is a CVSS 6.5 medium-severity vulnerability in Apache Tomcat. Full technical analysis, mitigations , and exploit status — updated in real time.
2026-09-24 11:51 UTC -
web:osv.dev
Comprehensive vulnerability database for your open source projects and dependencies.
2026-09-24 11:51 UTC -
web:vulmon.com
Vulnerability Summary Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 up to and including 11.0.25, from 10.1.0-M1 up to and including 10.1.58, from 9.0.0-M1 up to and including 9.0.121. The following versions were EOL at ...
2026-09-24 11:51 UTC -
web:vulners.com
CVE-2026-73581 🗓️ 23 Sep 2026 04:08:53 Reported by apache Type cve 🔗 web.nvd.nist.gov 👁 11 Views
2026-09-24 11:51 UTC -
web:www.cvefind.com
Full details for CVE-2026-73581 : technical description, impact, CVSS/EPSS scores, linked CWE, CAPEC, affected CPEs, disclosure date, and mitigation options.
2026-09-24 11:51 UTC -
web:www.nmmapper.com
cve details for CVE-2026-73581 - Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore viewing details and related vulnerabilities.
2026-09-24 11:51 UTC -
web:www.rapid7.com
CVE-2026-73581 : Apache Software Foundation Apache Tomcat: Improper Check for Certificate Revocation vulnerability in Apache Tomcat. View severity, references, and remediation details from Rapid7.
2026-09-24 11:51 UTC -
web:www.tenable.com
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected ...
2026-09-24 11:51 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-73581.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-73581",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T15:19:35.322766Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T15:19:40.273Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2026-09-23T18:10:39.638Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/23/19"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Apache Tomcat",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "11.0.25",
"status": "affected",
"version": "11.0.0-M1",
"versionType": "semver"
},
{
"lessThanOrEqual": "10.1.59",
"status": "affected",
"version": "10.1.0-M1",
"versionType": "semver"
},
{
"lessThanOrEqual": "9.0.121",
"status": "affected",
"version": "9.0.0.M1",
"versionType": "semver"
},
{
"lessThanOrEqual": "8.50.100",
"status": "affected",
"version": "8.5.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "8.5.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "arpitjain099 (https://github.com/arpitjain099)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.</p><p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121.</p><p>The following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100. Other unsupported versions may also be affected.</p><p>Users are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue.</p>"
}
],
"value": "Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.121.\n\n\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: from 8.5.0 through 8.5.100.\u00a0Other unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 11.0.26, 10.1.59, 9.0.122, which fixes the issue."
}
],
"metrics": [
{
"other": {
"content": {
"text": "moderate"
},
"type": "Textual description of severity"
},
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-299",
"description": "CWE-299 Improper Check for Certificate Revocation",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T11:08:53.212Z",
"orgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"shortName": "apache"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09",
"assignerShortName": "apache",
"cveId": "CVE-2026-73581",
"datePublished": "2026-09-23T11:08:53.212Z",
"dateReserved": "2026-08-13T07:31:17.111Z",
"dateUpdated": "2026-09-23T18:10:39.638Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}